โ† All CDPSE Flashcard Decks

Risk Management Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management flashcards as text
  1. A CDPSE is evaluating a third-party vendor that processes personal health information on behalf of the organization. Which risk management step should be performed FIRST?

    Answer: Conduct a vendor privacy risk assessment

    A vendor privacy risk assessment identifies the scope and nature of risk before decisions about agreements or audits can be meaningfully made.

  2. Which of the following BEST describes residual risk in a data privacy context?

    Answer: Risk that remains after privacy controls have been implemented

    Residual risk is what remains after controls are applied; it must be evaluated to determine if it falls within the organization's risk appetite.

  3. An organization's risk appetite for data privacy is defined as low. A proposed marketing analytics project carries moderate privacy risk. What is the MOST appropriate response?

    Answer: Implement additional privacy controls to reduce risk to an acceptable level

    When risk exceeds risk appetite, the appropriate response is to implement controls that bring residual risk within acceptable bounds before proceeding.

  4. Which metric is MOST useful when quantifying the likelihood component of a privacy risk?

    Answer: Historical frequency of similar threat events within the organization

    Internal historical frequency of similar events provides the most relevant and organization-specific input for likelihood estimation.

  5. A CDPSE discovers that an automated profiling system makes decisions about loan eligibility using personal data without human review. Which privacy risk category BEST describes this situation?

    Answer: Automated decision-making risk

    Automated decision-making risk arises when systems make significant decisions about individuals without human oversight, a concern addressed by regulations like GDPR Article 22.

  6. When performing a Data Protection Impact Assessment (DPIA), what is the primary purpose of identifying risk owners?

    Answer: To ensure accountability for treating or accepting identified privacy risks

    Risk owners are accountable for taking action on identified risks, ensuring that treatment plans are executed and residual risk is monitored.

  7. An organization operates in a jurisdiction that has enacted a new data privacy law. How should this be reflected in the privacy risk register?

    Answer: Create a new risk entry for regulatory non-compliance exposure

    New regulatory requirements introduce compliance risk that must be formally documented and tracked in the risk register.